{
  "fixes": {
    "slug": "complycube",
    "name": "ComplyCube",
    "listing": "https://www.anchorterminal.com/tools/complycube",
    "markdown": "# Fix list: ComplyCube\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/complycube, the October 2026 research run, assessed 8 October 2026. Grade B, 63.7 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on ComplyCube: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 27 out of 100, up to 9.1 more on the total\n\nWhy it scored 27: No x402, MPP or L402 (0). Starter is $99 a month and Core $299, each converted to usage credits, with per-check prices public (a document check is $1.05 on Starter and $0.75 on Core). Growth and Enterprise are quoted by sales, and several services show no price (17). The sandbox is free and returns dummy results. The 14-day trial of 50 checks starts when the account is activated from Test to Live, and whether that asks for a card wasn't established (10). Signup and key creation need a person in the Web Portal (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Security \u0026 auth, 52 out of 100, up to 8.4 more on the total\n\nWhy it scored 52: One test key and one live key per account, sent in the `Authorization` header, rotated from the Web Portal. No scopes, and the docs say keys carry many privileges. The pricing table lists IP whitelisting (15). Test and live are separate, short-lived SDK tokens keep keys out of client code, and five portal roles limit who can manage keys. Keys have no read-only mode and deletes need no confirmation (8). Responses carry document data supplied by end users and adverse media text. No injection guidance was found (3). Audit log API with team member, trigger, action and field-level diff, covering API keys and allowed IPs among 17 resource types (14). ISO 27001:2022, SOC 2 Type II, Cyber Essentials and regular penetration testing are stated. No `security.txt` (404), disclosure policy or bug bounty was found, and the trust centre couldn't be read (12).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 3. Agent ergonomics, 60 out of 100, up to 6.5 more on the total\n\nWhy it scored 60: `pageSize` from 1 to 1,000 (default 100) and omitted null properties size responses. No field selection (12). `page` and `pageSize` plus created and updated date filters on every list, and attribute filters per endpoint. A badly formed filter returns 200 with no results (17). Errors return `type`, `message` and `param`, with 29 named processing errors on 422, several telling the end user what to retake (15). No idempotency keys or safe-retry guidance for creates. Duplicate handling is documented for webhooks only (3). Official client libraries for Node.js, Python, PHP and .NET. A document check takes at least four calls (client, document, image upload, check) (13).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 4. Schema \u0026 documentation, 78 out of 100, up to 3.6 more on the total\n\nWhy it scored 78: Public OpenAPI 3.0.0 spec, version 1.7.3, with 52 operations on 35 paths, linked from the integration page. Company search, address search and redaction are in the reference but not in the spec (22). `llms.txt` on the docs host and every page as Markdown (10). All 52 operations have a summary and 14 a description. Reference pages describe each attribute, and when not to use a method is rarely stated (12). Bodies are typed inline with 28 enums and 53 required lists, and the spec has no reusable component schemas (10). Reference pages carry request examples in cURL and four SDK languages, response examples and a table of 29 processing errors, while the spec has no examples and only a default error response (12). The path carries v1 and a versioning policy lists releases to 1.7.3 without dates. The product changelog is dated (12).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 5. Reliability, 84 out of 100, up to 3.2 more on the total\n\nWhy it scored 84: Graded on the REST API, hosted lines. Statuspage at status.complycube.com with API, Web Portal, Hosted Solution and each check type as components for Europe, US, Asia-Pacific and Middle East (20). The incident feed shows nothing in the 90 days to 8 October 2026, and its newest entry is a 21-minute minor Document Check incident on 8 August 2022 (30). Limits published as 10 requests a second live and 5 in the sandbox (15). 429 is documented with exponential backoff and jitter starting at 30 seconds, but no Retry-After header and no idempotency keys for writes were found (9). The pricing table lists an SLA as a plan feature and Enterprise advertises SLA-backed uptime, but no SLA text or figure is published (0). The API is generally available at v1 (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 6. Transparency \u0026 trust, 63 out of 100, up to 3.2 more on the total\n\nMade of editorial 43, provenance 82.\n\nWhy it scored 63: Closed service. The terms of service carry no date, name ComplyCube without the legal entity, and are written around website use, Goods and Paid Content. The mobile and web SDK repositories and the PHP library are MIT (9). The privacy policy names Teemo Technology Ltd, says ComplyCube is a processor, uses client data for improvement only in anonymised or aggregated form, and answers a client's deletion request within 30 days. The pricing table gives 12 months of retention on Starter and indefinite above. The policy carries no date and no public DPA was found (16). A versioning policy lists changes treated as backward compatible. No deprecation notice period was found (6). Twelve data residency locations are published and AWS is named as host. The subprocessor list sits in the trust centre, which is drawn by script and wasn't read (12).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Domain age: complycube.com, registered 2018-05-24 (8 years) (11 of 15)\n- Terms of service: read, states 4 of the 7 things a reader expects (7.4 of 10)\n- Privacy policy: read, states 6 of the 8 things a reader expects (8.5 of 10)\n- security.txt: not found (0 of 10)\n\n## 7. Maintenance \u0026 community, 74 out of 100, up to 2.3 more on the total\n\nWhy it scored 74: The changelog's latest entry is dated 6 October 2026 (30). Three dated entries in the last 90 days, on 14 July, 27 August and 6 October 2026 (20). Closed service with a dated changelog and a support site. The public SDK repositories show three open issues between them. Response times weren't measurable (10). `@complycube/api` 1.1.14 was published on 15 April 2026 and `complycube` 1.1.8 on PyPI on 8 December 2025. The PHP library was last pushed in June 2026. No entry in the official MCP registry (10). The Node.js and Python libraries have no public source repository, so tests and CI couldn't be seen. The Node.js package depends on axios ^1.15.0 (4).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: the trust centre at trust.complycube.com (drawn by script on Vanta), so the subprocessor list, the SOC 2 report status and any DPA there weren't read\n- unchecked: whether signup or activating the 14-day trial asks for a payment card. The portal signup page is drawn by script\n- unchecked: which plan the single-price rows of the pricing table belong to (age estimation, proof of address, fraud intelligence, continuous monitoring). The page text didn't show the column\n- unchecked: the .NET library on NuGet and the Postman collection\n- Whether a service agreement or DPA other than the public terms of service governs paid accounts. None was found on a public page\n- Whether 429 responses carry a Retry-After header. None is documented\n- The docs compliance table says SOC 2 Type II (Compliant), and whether an audit report exists wasn't established\n- The docs `llms.txt` and each Markdown page end with GitBook's block of instructions addressed to AI agents (query the docs with an `ask` parameter). It wasn't acted on\n\n## Weaknesses\n\n- One API key per environment with no scopes. The docs say keys carry many privileges\n- No idempotency keys, and no Retry-After header documented for 429 responses\n- The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page\n- No `security.txt`, disclosure policy or bug bounty found, and the trust centre is drawn by script\n- Company search, address search and redaction endpoints are in the API reference but not in the OpenAPI spec\n- The ComplyCube MCP server serves documentation only and cannot reach account data\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Send the key bare in the `Authorization` header, with no Bearer prefix. Keys start `test_` or `live_`\n- Create a client first, then documents or live photos for it, then `POST /v1/checks` with the client and upload IDs\n- Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds\n- A badly formed filter returns 200 with no results, so check filter names before trusting an empty list\n- Checks are asynchronous. Subscribe to webhooks, verify the `ComplyCube-Signature` HMAC-SHA256 header, and expect duplicate and out-of-order events\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "B",
    "score": 63.7,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 27,
        "maxGain": 9.1,
        "reason": "No x402, MPP or L402 (0). Starter is $99 a month and Core $299, each converted to usage credits, with per-check prices public (a document check is $1.05 on Starter and $0.75 on Core). Growth and Enterprise are quoted by sales, and several services show no price (17). The sandbox is free and returns dummy results. The 14-day trial of 50 checks starts when the account is activated from Test to Live, and whether that asks for a card wasn't established (10). Signup and key creation need a person in the Web Portal (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 52,
        "maxGain": 8.4,
        "reason": "One test key and one live key per account, sent in the `Authorization` header, rotated from the Web Portal. No scopes, and the docs say keys carry many privileges. The pricing table lists IP whitelisting (15). Test and live are separate, short-lived SDK tokens keep keys out of client code, and five portal roles limit who can manage keys. Keys have no read-only mode and deletes need no confirmation (8). Responses carry document data supplied by end users and adverse media text. No injection guidance was found (3). Audit log API with team member, trigger, action and field-level diff, covering API keys and allowed IPs among 17 resource types (14). ISO 27001:2022, SOC 2 Type II, Cyber Essentials and regular penetration testing are stated. No `security.txt` (404), disclosure policy or bug bounty was found, and the trust centre couldn't be read (12).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 60,
        "maxGain": 6.5,
        "reason": "`pageSize` from 1 to 1,000 (default 100) and omitted null properties size responses. No field selection (12). `page` and `pageSize` plus created and updated date filters on every list, and attribute filters per endpoint. A badly formed filter returns 200 with no results (17). Errors return `type`, `message` and `param`, with 29 named processing errors on 422, several telling the end user what to retake (15). No idempotency keys or safe-retry guidance for creates. Duplicate handling is documented for webhooks only (3). Official client libraries for Node.js, Python, PHP and .NET. A document check takes at least four calls (client, document, image upload, check) (13).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 78,
        "maxGain": 3.6,
        "reason": "Public OpenAPI 3.0.0 spec, version 1.7.3, with 52 operations on 35 paths, linked from the integration page. Company search, address search and redaction are in the reference but not in the spec (22). `llms.txt` on the docs host and every page as Markdown (10). All 52 operations have a summary and 14 a description. Reference pages describe each attribute, and when not to use a method is rarely stated (12). Bodies are typed inline with 28 enums and 53 required lists, and the spec has no reusable component schemas (10). Reference pages carry request examples in cURL and four SDK languages, response examples and a table of 29 processing errors, while the spec has no examples and only a default error response (12). The path carries v1 and a versioning policy lists releases to 1.7.3 without dates. The product changelog is dated (12).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 84,
        "maxGain": 3.2,
        "reason": "Graded on the REST API, hosted lines. Statuspage at status.complycube.com with API, Web Portal, Hosted Solution and each check type as components for Europe, US, Asia-Pacific and Middle East (20). The incident feed shows nothing in the 90 days to 8 October 2026, and its newest entry is a 21-minute minor Document Check incident on 8 August 2022 (30). Limits published as 10 requests a second live and 5 in the sandbox (15). 429 is documented with exponential backoff and jitter starting at 30 seconds, but no Retry-After header and no idempotency keys for writes were found (9). The pricing table lists an SLA as a plan feature and Enterprise advertises SLA-backed uptime, but no SLA text or figure is published (0). The API is generally available at v1 (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 63,
        "maxGain": 3.2,
        "reason": "Closed service. The terms of service carry no date, name ComplyCube without the legal entity, and are written around website use, Goods and Paid Content. The mobile and web SDK repositories and the PHP library are MIT (9). The privacy policy names Teemo Technology Ltd, says ComplyCube is a processor, uses client data for improvement only in anonymised or aggregated form, and answers a client's deletion request within 30 days. The pricing table gives 12 months of retention on Starter and indefinite above. The policy carries no date and no public DPA was found (16). A versioning policy lists changes treated as backward compatible. No deprecation notice period was found (6). Twelve data residency locations are published and AWS is named as host. The subprocessor list sits in the trust centre, which is drawn by script and wasn't read (12).",
        "blend": "editorial 43, provenance 82",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 74,
        "maxGain": 2.3,
        "reason": "The changelog's latest entry is dated 6 October 2026 (30). Three dated entries in the last 90 days, on 14 July, 27 August and 6 October 2026 (20). Closed service with a dated changelog and a support site. The public SDK repositories show three open issues between them. Response times weren't measurable (10). `@complycube/api` 1.1.14 was published on 15 April 2026 and `complycube` 1.1.8 on PyPI on 8 December 2025. The PHP library was last pushed in June 2026. No entry in the official MCP registry (10). The Node.js and Python libraries have no public source repository, so tests and CI couldn't be seen. The Node.js package depends on axios ^1.15.0 (4).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      }
    ],
    "provenance": [
      {
        "label": "Domain age",
        "value": "complycube.com, registered 2018-05-24 (8 years)",
        "points": 11,
        "max": 15
      },
      {
        "label": "Terms of service",
        "value": "read, states 4 of the 7 things a reader expects",
        "points": 7.4,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "read, states 6 of the 8 things a reader expects",
        "points": 8.5,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "not found",
        "points": 0,
        "max": 10
      }
    ],
    "unchecked": [
      "unchecked: the trust centre at trust.complycube.com (drawn by script on Vanta), so the subprocessor list, the SOC 2 report status and any DPA there weren't read",
      "unchecked: whether signup or activating the 14-day trial asks for a payment card. The portal signup page is drawn by script",
      "unchecked: which plan the single-price rows of the pricing table belong to (age estimation, proof of address, fraud intelligence, continuous monitoring). The page text didn't show the column",
      "unchecked: the .NET library on NuGet and the Postman collection",
      "Whether a service agreement or DPA other than the public terms of service governs paid accounts. None was found on a public page",
      "Whether 429 responses carry a Retry-After header. None is documented",
      "The docs compliance table says SOC 2 Type II (Compliant), and whether an audit report exists wasn't established",
      "The docs `llms.txt` and each Markdown page end with GitBook's block of instructions addressed to AI agents (query the docs with an `ask` parameter). It wasn't acted on"
    ],
    "weaknesses": [
      "One API key per environment with no scopes. The docs say keys carry many privileges",
      "No idempotency keys, and no Retry-After header documented for 429 responses",
      "The only published terms are undated, read as website terms and cite the Data Protection Act 1998. No service agreement or DPA was found on a public page",
      "No `security.txt`, disclosure policy or bug bounty found, and the trust centre is drawn by script",
      "Company search, address search and redaction endpoints are in the API reference but not in the OpenAPI spec",
      "The ComplyCube MCP server serves documentation only and cannot reach account data"
    ],
    "agentNotes": [
      "Send the key bare in the `Authorization` header, with no Bearer prefix. Keys start `test_` or `live_`",
      "Create a client first, then documents or live photos for it, then `POST /v1/checks` with the client and upload IDs",
      "Stay under 10 requests a second live and 5 in the sandbox. On 429, back off exponentially with jitter, starting at 30 seconds",
      "A badly formed filter returns 200 with no results, so check filter names before trusting an empty list",
      "Checks are asynchronous. Subscribe to webhooks, verify the `ComplyCube-Signature` HMAC-SHA256 header, and expect duplicate and out-of-order events"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
